App Privacy Policy
Version 1.2 · 2026-09-09
This policy covers the unflat mobile app. The policy at unflat.finance/privacy.html covers this website and its waiting list, and is a separate document.
Who we are
unflat S.r.l. is the data controller for this app.
- Address: Via del Lauro 9, 20121 Milano, Italy
- VAT / P.IVA: 14711040965
- PEC: unflat@legalmail.it
- Privacy contact: alessandro.prandini@unflat.eu
If you think we have handled your data badly, you can complain to the Garante per la protezione dei dati personali, the Italian supervisory authority (garanteprivacy.it).
What this app is
unflat is a savings app. You deposit euros, they are converted to a dollar-denominated stablecoin, and that balance earns yield through a lending protocol. unflat never holds your money: it sits in a smart account that only you control.
That shapes this policy more than anything else. Some of your activity is recorded on a public blockchain, which we cannot edit or erase. We say so plainly below rather than implying otherwise.
The data we hold, and why
Your account
When you sign in we collect your email address, or the identifier Apple or Google gives us if you use those buttons. Our authentication provider, Privy, creates a stable account identifier for you and generates the keys for your smart account.
We use this to sign you in and to recognise you across our systems. Legal basis: performance of our contract with you.
Your smart account address and on-chain activity
Every account has a blockchain address on Base. Your deposits, withdrawals and yield are recorded against that address on a public ledger.
This part is permanent and public. Anyone can read it, it is not in a database we control, and neither we nor you can delete it. This is how a non-custodial product works, and it is the trade-off for us never holding your funds. We store the address itself so we can show you your balance and route your deposits.
Legal basis: performance of our contract. The public ledger is not something we control.
Verifying your identity
To use the euro bank transfer rail, you have to pass an identity check. That check is run by Iron (MoonPay Enterprise) using Sumsub, inside a web page we open for you.
We do not receive your documents, your selfie, your occupation or your source of funds. They go to Iron and its provider, never to us. What comes back to us is a status: pending, active, rejected.
We do store your email, your Iron customer identifier and that status.
Legal basis: compliance with a legal obligation — anti-money-laundering rules that apply to Iron and MoonPay as regulated providers.
Your bank details
If you set up a euro account or a payout to your bank, we store the IBAN, the account holder name, the BIC and the bank name, and the last four digits separately so we can show you which account you chose. When money arrives, we record the sender's name and the last four digits of their IBAN so we can match the payment to you.
IBANs and names are encrypted in our database. That protects them if the database is ever exposed. It does not hide them from us: our own systems can decrypt them to run a payout.
Legal basis: performance of our contract, and legal obligation for the transaction records.
Card payments
If you pay by card, MoonPay runs the payment and its own identity checks. We never see your card number. We store a reference to the transaction, your address, the country and the IP address MoonPay reports.
MoonPay decides on its own how to handle the data you give it directly. For that part MoonPay is its own controller and its own policy applies.
Legal basis: performance of our contract, and legal obligation for the records.
Notifications
If you turn notifications on, we store a push token for your device so we can tell you when a deposit or withdrawal lands.
Legal basis: your consent, given through the permission prompt. Turn it off under Settings → Notifications, or in your device settings.
We send two kinds of email. Transactional email — a deposit receipt — arrives whatever your settings, because it is part of the service. Lifecycle email helps you get set up and tells you about your savings.
To do this we keep a profile with your email, your account identifier, your language and time zone, timestamps for things like when you signed up and when you first deposited, your identity-check status, and a recent snapshot of your balance.
Legal basis: legitimate interest in helping you use a product you signed up for.
Every email we send carries an unsubscribe link at the bottom. Using it stops lifecycle email. Deposit receipts still arrive, because they are part of the service. You can also write to the privacy contact above and we will unsubscribe you.
Lifecycle email starts on when you accept the terms, and the Terms screen says so before you accept. Until 2026-09-09 it started off and was switched on under Settings → "Emails from unflat"; if you had switched it on or off there, that choice still stands and was not reset.
Our email is delivered by Resend.
How the app is used
We record what happens in the app: which screens you open, which buttons you tap, whether a deposit succeeded or failed. Every event also carries your app version, build number and platform.
We use PostHog, on servers in the European Union.
Legal basis: legitimate interest in understanding whether the product works.
Session recordings
The app records your screen while you use it, so we can see where people get stuck. Recordings are captured by PostHog and stored in the European Union.
We hide sensitive parts of the screen on your device, before anything is sent: your email address, your balance, amounts you type, your transaction list, your bank details, the identity-check screens and the card payment screen.
Legal basis: legitimate interest.
Recording is on by default and the Terms screen tells you so before you accept. To object, write to the privacy contact above and we will switch recording off for your account.
Until 2026-09-09 there was a switch under Settings → "Session recordings". It was removed, but the choice was not: if you had turned recording off on a device, that device is still not recorded.
Measuring which ad brought you here
When you install unflat after seeing one of our ads, we measure which campaign brought you. This is done by AppsFlyer, acting as our processor.
What is processed: your device's advertising ID — an identifier you can reset at any time in your device settings — your IP address, technical details of your device such as model, operating system version, language and time zone, and the install referrer string the app store passes to the app. The events sent are the install and the app opening.
What is not: no financial data, no identity-check data, no name or email. We do not link the advertising ID to your unflat account.
Recipients: AppsFlyer Ltd (Herzliya, Israel), and — for installs that came from their ads — Meta Platforms Ireland and Reddit Inc. (United States), which receive the notification that an install happened.
Purpose: attribution and measurement of advertising campaigns. We do not build advertising profiles and we do not personalise ads on this basis.
Legal basis: legitimate interest.
How to stop it: where this is switched on at all, it is asked for as an optional tick box on the Terms screen when you first accept, and leaving it unticked means it never runs. You can also reset or delete your advertising ID in your device settings, or write to the privacy contact above.
Until 2026-09-09 there was also a switch under Settings → "Campaign measurement". It was removed; a choice already recorded there still stands.
Accepting these terms
When you accept our terms we record that you did: your account identifier, your email, which version you accepted, a fingerprint of the text, the time, and your platform, operating system version and app version.
Legal basis: legitimate interest in being able to show what you agreed to.
The onboarding questions
Shortly after you join, we may ask you five optional questions: what brings you to unflat, what best describes you, where your savings sit today, how much you might put in over the next six months, and your age band.
Some specifics, because they are the point:
- Every question is skippable, and skipping is one tap. You can skip the first one and never see the rest.
- The answers change nothing about your account. They do not affect what you can do, what you can deposit, what anything costs, or any decision we make about you. There is no such decision. They exist so we can understand who is using unflat and split our own product metrics by the answers.
- No free text. Every question is a fixed set of options.
- We ask your age band, not your date of birth. A range, not an identifier.
- We do not ask about your income, your net worth or where your money comes from. Those belong to the identity check, and we are not going to duplicate a regulated question in an optional survey.
Legal basis: your consent, given by answering. Skipping is a refusal and costs you nothing.
Who else sees your data
| Who | Role | What for |
|---|---|---|
| Privy | Processor | Sign-in and smart account keys |
| Supabase | Processor | Our database and backend |
| Iron (MoonPay Enterprise) | Processor, and own controller for the regulated part | Identity checks, euro account, SEPA transfers |
| Sumsub | Iron's sub-processor | Runs the identity check for Iron |
| MoonPay | Own controller | Card payments and its own identity checks |
| Coinbase | Own controller | Card and bank purchase, if you use it |
| PostHog | Processor | Analytics and session recordings |
| AppsFlyer | Processor | Campaign measurement |
| Meta Platforms Ireland, Reddit Inc. | Own controllers | Told that an install happened, for installs from their ads |
| Expo | Processor | Delivering push notifications and app updates |
| Resend | Processor | Sending email |
We do not sell your data. Nobody on this list receives it for their own marketing except Meta and Reddit, and only the install notification described above.
Where your data goes
PostHog, which holds your analytics events and session recordings, stores them in the European Union.
AppsFlyer is in Israel, a country the European Commission has recognised as providing an adequate level of data protection, and has told us it hosts data in the EU. Reddit Inc. is in the United States.
Some of our other providers may process data outside the European Economic Area. Where they do, we rely on an adequacy decision or on standard contractual clauses approved by the European Commission. If you want the specifics for a given provider, write to us and we will tell you.
How long we keep it
We keep your data while you have an account.
If you delete your account, we keep your identity-verification and banking records for 10 years. Anti-money-laundering law requires it: we are obliged to be able to reconstruct who we onboarded and what moved through their account. Most of the rest goes at once, and a small part is kept with everything that identifies you stripped out of it.
"Deleting your account" below sets out all three categories, record by record. Those lists describe our own systems. Our providers apply their own retention periods to the data they hold, and deleting your account here does not by itself erase a copy held by a provider that is its own controller.
After 10 years the kept records are deleted automatically, by a scheduled job. We do not wait to be asked.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to it. Where we rely on legitimate interest you can object at any time, and where we rely on consent you can withdraw it without affecting what we did before.
Email alessandro.prandini@unflat.eu. We reply within one month.
You can also complain to the Garante.
Deleting your account
Settings → Delete account removes your account. A record ends up in one of three places, and here is which.
1. Deleted — the record is gone:
- your sign-in identity, so you can no longer log in
- your answers to the onboarding questions
- your push token, so we cannot notify you again
- your referral records
- your feedback and survey answers, and your subscription record
- everything held by our previous banking partner integration, including the identity record and the notifications it sent us
- your euro-sale records and any deposit that never completed
Your analytics profile, every event recorded against it, and every session recording of you are deleted too. We ask PostHog to delete them at the moment you delete your account; PostHog processes those deletions in batches, so they disappear within its deletion cycle rather than the same second.
2. Kept, with everything that identifies you removed:
- your card-payment records. We erase the wallet address, your account identifier, your IP address, your country and the raw payment data we received from the payment provider. What remains is the transaction — the amount, the currency and the date — which we are required to be able to produce.
- your acceptance of these terms. We keep which version you accepted and when, and remove your email and your device details. This one has no end date: it is the proof that the terms were accepted, and it stops being about you once your email is gone.
3. Kept in full for 10 years, then deleted automatically:
- your identity-verification record, including the email address on it
- your bank details, your euro account and its transaction history
- your transaction history with our current banking partner, and the notifications they sent us about it
Anti-money-laundering law requires us to keep this third group — Article 17(3) of the GDPR and article 31 of D.lgs. 231/2007. You can still ask us to delete it: we will reply within one month and tell you which records are covered by that obligation and which are not. What we cannot do is shorten the 10 years for the records that are covered.
Your email address stays in your identity-verification record. When you delete your account we keep the record our banking partner created for the identity check, including the email address on it, for 10 years. Anti-money-laundering rules require it, and a record with no identifier on it would not satisfy them. Everything else in group 3 is deleted on the same day as that record.
Your messaging profile and the messages we sent you are also kept, so we have a record of what we sent and can show we honoured your choices. This is a separate decision from the anti-money-laundering one above and rests on our legitimate interest, not on AML law. Once your account is deleted we stop sending you lifecycle email and push notifications. The kept profile is a record of what we sent, not a list we send to.
We cannot delete your blockchain activity. It is on a public ledger.
Automated decisions
We do not make any automated decisions about you, and we do not profile you to decide anything. Nothing in the app decides what you can do based on your data. The onboarding questions in particular affect nothing: no eligibility, no limit, no price, no decision.
Children
unflat is for adults. You must be 18 or over. We do not knowingly collect data about anyone under 18. If you believe a child has an account, write to us and we will remove it.
Security
Bank details and account holder names are encrypted in our database. Access to our systems is restricted to the people who need it. Your funds are held in a smart account only you control, so we cannot move them.
Changes
If we change this policy we will update the version and date at the top. If a change matters to you, we will tell you in the app before it takes effect.
Version 1.2 · 9 September 2026 · unflat S.r.l.